OPENWRT/LEDEÔ¶³Ì´úÂëÖ´Ðзì϶·çÏÕ¹«¸æ

°ä²¼¹¦·ò 2020-03-25

·ì϶±àºÅºÍ¼¶±ð


CVE±àºÅ£ºCVE-2020-7982£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬CVSS·ÖÖµ£º8.1


Ó°Ïì°æ±¾


OPENWRT 18.06.0µ½18.06.6°æ±¾ÒÔ¼°OPENWRT 19.07.0°æ±¾

»ùÓÚOPENWRT¹Ì¼þÔì×÷µÄLEDE¹Ì¼þ 17.01.0µ½17.01.7 °æ±¾

±ÈÁ¦ÀϵÄÒѾ­²»ÊÜÖ§³ÖµÄ°æ±¾ÀýÈçOPENWRT 15.05 ÒÔ¼°LEDE 17.01 ÊÜ·ì϶ӰÏìÇÒ²»ÊÜÖ§³ÖÎÞ·¨½¨¸´


·ì϶¸ÅÊö


OpenWrtÊÇÒ»Ì×Õë¶ÔǶÈëʽÉ豸µÄLinux²Ù×÷ϵͳ¡£


OPENWRT¹Ì¼þʹÓõİü½âÎöÖÎÀíÆ÷OPKG FORK´æÔÚÂß¼­ÃýÎó£¬ÖÎÀíÆ÷ºöÂÔÁËÊðÃû¿âÖÐÔ̺¬µÄSHA-256УÑéÖµ¡£ÕâÒâζ×ÅÖ±½Óͨ¹ýÖÎÀíÆ÷×°Öà IPKÀëÏß×°ÖðüʱÊDz»¾­¹ýУÑéµÄ£¬¶ø¹¥»÷ÕßÔòÄܹ»ÀûÓÃÕâ¸ö·ì϶װÖÃΣÏÕµÄÄÚÈÝ¡£ÓÉÓÚ°ü½âÎöÖÎÀíÆ÷×ÔÉíÊÇÒÔROOTȨÏÞÔËÐеÄÒò¶øÈ¨ÏÞ¼«¶È¸ß£¬ÆäȨÏÞÄܹ»Õë¶ÔÕû¸öÎļþϵͳ²»»áÊܵ½È¨ÏÞÖÎÀí¡£¹¥»÷ÕßÈôÊÇͨ¹ýαÔìµÄ·½Ê½×°ÖÃÓµÓжñÒâ´úÂëµÄ .IPK×°ÖðüÔòÄܹ»»ñµÃROOTȨÏÞ£¬½ø¶øÒ²Äܹ»½ÚÔìÕû¸ö·ÓÉÆ÷¡£


ΪÁËÀûÓô˷ì϶£¬¹¥»÷Õß±ØÒª·¢ÆðÖÐÑëÈ˹¥»÷ (MITM)£¬ÌṩÓÐЧÇÒÒÑÊðÃûµÄ°üË÷Òý£¨ÀýÈ磬´Ódownloads.openwrt.or g»ñµÃµÄË÷Òý£©ºÍÒ»¸ö»ò¶à¸öÓµÓÐÓë´æ´¢¿âË÷ÒýÖÐÖ¸¶¨µÄÒ»Ñù´óÓ×µÄαÔì.ipk°ü£¬Í¬Ê±ÔÚÊܺ¦ÏµÍ³ÉÏŲÓá°opkg install¡±ºÅÁî¡£


·ì϶ÑéÖ¤


ÔÝÎÞPoC/EXP¡£


½¨¸´½¨Òé


Ŀǰ³§ÉÌÒѰ䲼OpenWrtа汾£¬Á´½Ó£ºhttps://openwrt.org/advisory/2020-01-31-1¡£

»òÕߣ¬ÒªÔÚ²»Éý¼¶Õû¸ö¹Ì¼þµÄÇé¿öϸüÐÂopkg°ü×ÔÉí£¬Äܹ»ÔÚ¸üÐÂËùÓд洢¿âºóʹÓÃÒÔϺÅÁ

cd /tmp

opkg update

opkg download opkg

zcat ./opkg-lists/openwrt_base | grep -A10 "Package: opkg" | grep SHA256sum

sha256sum ./opkg_2020-01-25-c09fe209-1_*.ipk

±ÈÁ¦Á½¸öУÑéºÍ£¬ÈôÊÇÆ¥Å䣬³ÖÐø×°Ö÷¨Ê½°ü£º

opkg install ./opkg_2020-01-25-c09fe209-1_*.ipk


²Î¿¼Á´½Ó


https://openwrt.org/advisory/2020-01-31-1